MAL-2026-12816
Dashboard / Malicious Package / MAL-2026-12816
MAL-2026-12816
Published: 5 Aug 2026Last Modified: 5 Aug 2026
Summary: Malicious code in wolverinechat (npm)
Details: Source: amazon-inspector (6ad1c6bad5ee8d3cb562503b94d5534ba2c98ad5b4854c073e1482d59ab8687e) package.json declares a preinstall hook that runs index.js during `npm install`. The script reads /etc/passwd, /etc/hosts, os.hostname(), os.userInfo().username, the user's home directory, dns.getServers(), and package metadata, then POSTs the collected data via HTTPS to the hardcoded subdomain 7ckdbwo9f8dtrg8y36sbe4e8lzrqfg35.oastify.com (Burp Collaborator OAST callback). The exfiltration fires automatically at install time without user interaction.
Affected packages
Package
Name: wolverinechat
Purl: pkg:npm/wolverinechat
Affected ranges
Type: N/A
Events:
Introduced- None
Fixed -None
Affected versions
1.0.1
